spot_img

Date:

Share:

Commentary: Strengthening digital defences ahead of World Password Day

With World Password Day approaching on 7 May, ManageEngine South Africa is highlighting the importance of stronger password practises as cyber risks continue to rise for local businesses.

According to David C. Howell, Regional Sales Director at ManageEngine South Africa, many organisations are under mounting pressure to move beyond outdated password habits as cybercriminals continue to exploit weak or reused credentials. “Password security remains one of the simplest yet most frequently overlooked elements of cybersecurity. In South Africa, where businesses are rapidly accelerating digital transformation and employees often work across multiple devices and networks, the risks linked to poor password hygiene are becoming more pronounced,” said Howell.

Local data supports this concern. A TransUnion report shows that the account login stage has the highest rate of suspected digital fraud in the consumer life cycle in South Africa, driven by attempts at account takeover using stolen credentials, intercepted one-time passwords, and social engineering tactics. Often, attackers do not need sophisticated tools, instead exploiting compromised login details and human behaviour to gain access to accounts.

Howell added that this challenge is not unique to the local market, with global research reinforcing how persistent the problem remains. The Verizon 2025 Data Breach Investigations Report found that credential abuse remains the most common initial access vector in breaches, involved in over 22% of all confirmed non-error, non-misuse incidents.

“This demonstrates that even with advances in security tools, compromised credentials are still one of the easiest ways for attackers to gain access,” Howell explained. “We are seeing a clear shift towards passwordless authentication and stronger identity and access management frameworks, but adoption is still uneven, particularly among SMEs. The priority should be simple, practical steps: stronger passwords, multi-factor authentication, and better control over who has access to what.”

As organisations continue to expand their digital footprint, strengthening identity and access controls is a fundamental requirement for protecting systems, customer data, and user trust in an evolving threat landscape.

spot_img
spot_img

━ More like this

AI is forcing banks to rebuild their entire cyber architecture

Artificial intelligence is forcing financial institutions to rethink the foundations of cybersecurity as increasingly sophisticated AI-generated fraud exposes the limitations of traditional security systems. While...

Tax season: the window criminals plan for, and compliance can’t close

The South African tax season is in everybody’s calendar, including cybercriminals. Every year, from July to October, millions of South Africans log into SARS...

Kaspersky warns of a new StrikeShark campaign targeting organisations in Asia, Latin America and Europe with advanced malware

Kaspersky Global Research and Analysis Team has announced the discovery of a new sophisticated malicious campaign – StrikeShark. The attackers targeted multiple organisations worldwide,...

Data sovereignty, cybersecurity, and automation: What’s on the mind of CIOs today

Beyond maintaining stable systems, chief information officers (CIOs) are increasingly responsible for enabling digital growth and protecting organisational data. That's on top of ensuring...

Kaspersky detected over 336 unique domains impersonating the official World Cup website

Kaspersky warns users to be careful with unofficial streaming and betting platforms to avoid losing money and personal data. The World Cup 2026 kicked off...
spot_img